A sustained DDoS attack against a mid-size enterprise costs the attacker approximately $50-$200 per hour using DDoS-as-a-service platforms. The cost to the target: $50,000-$500,000 per hour in lost revenue, engineering response time, and operational disruption. This 500-to-1,000x cost asymmetry is not a vulnerability in any specific technology -- it is a structural feature of how the internet works. Defense strategies that ignore this asymmetry will always overspend on the wrong controls.
The Attack Cost Structure
Volumetric DDoS attacks are available on underground markets at well-documented price points. A 100 Gbps attack for 1 hour costs approximately $100-$300. An L7 application-layer attack (more sophisticated, harder to detect) costs more per hour but requires less bandwidth. Residential proxy networks for credential stuffing cost $1-$3 per GB of traffic. A well-resourced attacker with a $10,000 budget can sustain a multi-day campaign against most mid-market targets.
The attack cost is largely independent of the size of the target. Whether you have $10M or $1B in annual revenue, the cost to attack you with commodity tooling is the same. The cost to defend scales with revenue, making smaller organizations proportionally more attractive targets for extortion-motivated attacks where the attacker can threaten continued attacks until a payment is made.
The Defense Cost Structure
Defense costs fall into two categories: capacity costs and operational costs. Capacity costs are the CDN, scrubbing, and bandwidth contracts that allow you to absorb large attacks. Operational costs are the engineering time and SOC attention required to manage attacks when they occur. The asymmetry matters more for operational costs than capacity costs: a $200 attack can require 40 hours of engineering time to mitigate if the defenses are not pre-configured correctly.
The investment case for upfront hardening is a function of this asymmetry. A $5,000 investment in correctly configured rate limits and WAF rules eliminates the 40-hour response cost for a $200 attack. At even one attack per year, the ROI is clear. For financial sector organizations in the current threat environment, which face multiple targeted attacks annually, the ROI is significantly higher.
Using Asymmetry to Prioritize Hardening
The asymmetry argument suggests a specific prioritization principle: harden the controls that reduce operational response cost first, before investing in capacity that only affects the upper bound of attacks you can absorb. A rate limit rule that blocks 99% of an L7 attack automatically costs zero engineering hours to maintain during an incident. A scrubbing center contract that requires manual traffic steering costs 4-8 engineering hours per incident. Both are valuable, but the rate limit rule produces more cost reduction per dollar invested.
The Extortion Equilibrium
For ransomware-adjacent DDoS extortion, the attacker's economics require that the payment demanded is above the attack cost but below the expected defense cost. If your defense cost per attack is $100,000 and the attack costs $200, extortion demands of $10,000-$50,000 are economically rational from the attacker's perspective. Reducing your defense cost through pre-configured automated mitigation to near-zero breaks this equilibrium: an extortion demand at any amount above near-zero is economically irrational for the target to pay. Hardening is both a technical and economic defense against extortion campaigns.
Quantify Your DDoS Defense ROI
DDactic's assessment identifies the specific configurations that reduce your operational response cost per attack, making the investment case concrete.
Run a Free Scan